Google has donated Longfellow, its zero-knowledge proof (ZKP) library, to the Post-Quantum Cryptography Alliance (PQCA), a foundation under the Linux Foundation Europe. Longfellow lets someone prove a single fact, such as being over 18, without handing over a name, an address, or a date of birth. The point of the transfer is to move the library out of one company's hands and into neutral stewardship where anyone can audit and adopt it.
Handing over one fact instead of an entire ID
Online age checks have long worked by passing along a photo of an identity document, or the date of birth printed on it. That is reliable for the party doing the checking, but the person being checked gives up far more than the single condition at issue: a name, an address, a document number. What happens to that data afterwards is invisible to them.
Zero-knowledge proofs close that gap. Using the information already held in a digital ID, the technique convinces the other side that a condition is satisfied, and reveals nothing else. Google designed Longfellow specifically for this pairing with digital IDs and released it as open source in 2025.
Built to sit on top of existing credential formats
Longfellow does not introduce a new kind of identity document. It lets developers build zero-knowledge protocols against credential formats already in circulation, including the ISO mdoc standard used for mobile driver's licenses, JWT, and W3C Verifiable Credentials.
Rather than pushing a new standard from scratch, the library adds a verification layer on top of digital IDs that are already being issued. That choice means wallet apps and issuers do not have to be rebuilt to swap in a more private proof method. It sidesteps the migration cost that usually stalls adoption.
The code lives in the google/longfellow-zk repository on GitHub, so developers can wire it into their own products as an age assurance mechanism.
Why a post-quantum alliance is the right home
PQCA was formed under the Linux Foundation in February 2024 to prepare for the day quantum computers break today's public-key cryptography, by producing high-assurance implementations of standardized post-quantum algorithms. Founding members include Amazon Web Services, Cisco, Google, IBM, NVIDIA, SandboxAQ, and the University of Waterloo, and the Open Quantum Safe project also sits under the alliance.
Identity credentials, once issued, stay in use for a decade or more. A proof built with today's cryptography should not become readable to a machine that arrives a few years later. Placing digital identity verification inside the post-quantum conversation looks like a decision made with that timescale in mind.
Longfellow is currently the subject of 2 independent security reviews by panels of academic and industry experts, with the reports published in the project documentation. Moving the library to a neutral body turns that kind of outside scrutiny into a standing arrangement rather than a one-off.
Interoperability is the remaining problem
Google says it will continue to develop and support Longfellow in the open, working with experts around the world. It also frames the harder part as collaboration between the public and private sectors, with the goal of a global, interoperable infrastructure that works across every device, browser, and wallet.
Age verification rules are tightening in many jurisdictions, so operators will need some mechanism regardless. Whether the only available option is "hand over the whole document" or whether "prove the condition and nothing more" is also on the table makes a large difference to the person on the other end. A library kept in a neutral place, auditable and free to adopt, is the groundwork that makes the second option practical.
Summary
Google has donated Longfellow, its zero-knowledge proof library for digital identity, to the PQCA under the Linux Foundation Europe. It allows a condition such as age to be proven on top of existing formats like ISO mdoc and W3C Verifiable Credentials. Handing it to an alliance built around post-quantum cryptography gives the library governance suited to credentials with long lifespans, plus a durable framework for third-party audits. Whether it becomes usable in practice now depends on how many wallets and browsers implement the same approach.
